Visible to the public Implementing Geo-Blocking and Spoofing Protection in Multi-Domain Software Defined Interconnects

TitleImplementing Geo-Blocking and Spoofing Protection in Multi-Domain Software Defined Interconnects
Publication TypeConference Paper
Year of Publication2017
AuthorsKumar, Himal, Mercian, Anu, Banerjee, Sujata, Russell, Craig, Sivaraman, Vijay
Conference NameProceedings of the 1st International Workshop on Security and Dependability of Multi-Domain Infrastructures
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4937-6
KeywordsGeo-Blocking, Internet Exchange Point, Metrics, pubcrawl, resilience, Resiliency, Router Systems, Router Systems Security, security, Security Intents, software defined networking
Abstract

Motivated by recent attacks like the Australian census website meltdown in 2016, this paper proposes a system for high-level specification and synthesis of intents for Geo-Blocking and IP Spoofing protection at a Software Defined Interconnect. In contrast to todays methods that use expensive custom hardware and/or manual configuration, our solution allows the operator to specify high-level intents, which are automatically compiled to flow-level rules and pushed into the interconnect fabric. We define a grammar for specifying the security policies, and a compiler for converting these to connectivity rules. We prototype our system on the open-source ONOS Controller platform, demonstrate its functionality in a multi-domain SDN fabric interconnecting legacy border routers, and evaluate its performance and scalability in blocking DDoS attacks.

URLhttps://dl.acm.org/citation.cfm?doid=3071064.3071065
DOI10.1145/3071064.3071065
Citation Keykumar_implementing_2017